PT-2025-51930 · Churchcrm · Churchcrm

Uartu0

·

Published

2025-12-17

·

Updated

2025-12-20

·

CVE-2025-68112

CVSS v3.1

9.6

Critical

VectorAV:N/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:N
Name of the Vulnerable Software and Affected Versions ChurchCRM versions prior to 6.5.3
Description ChurchCRM is an open-source church management system. A SQL injection flaw exists in the Event Attendee Editor. This allows authenticated users to execute arbitrary SQL commands, potentially leading to complete database compromise, administrative credential theft, and system takeover. Attackers could extract sensitive member data, authentication credentials, and financial information. The vulnerable component is the Event Attendee Editor. SQL injection is a code injection technique used to attack data-driven applications, in which malicious SQL statements are inserted into an entry field for execution.
Recommendations Upgrade to version 6.5.3 to address this issue.

Exploit

Fix

SQL injection

Weakness Enumeration

Related Identifiers

CVE-2025-68112
GHSA-HXF4-3VHP-WQCQ

Affected Products

Churchcrm